By NHI Mgmt Group Editorial TeamBased on SSH Communications Security: “PRESS RELEASE: SSH Communications Security Recognized as a Leader in all Categories in KuppingerCole’s 2025 Secure OT Access Report” (October 22, 2025)

TL;DR: Critical infrastructure teams are being judged on browser-based access, scalability and legacy compatibility, while SSH Communications Security’s PrivX OT was recognized by KuppingerCole in secure remote access for OT and ICS and the same week received an honorable mention in Gartner’s 2025 PAM Magic Quadrant, underscoring how critical infrastructure teams are being judged on browser-based access, scalability and legacy compatibility. The real issue is not analyst recognition, but whether PAM controls can govern distributed OT access without weakening operational continuity.


At a glance

What this is: SSH Communications Security’s article links analyst recognition for PrivX OT to the broader problem of securing distributed OT access across legacy and modern industrial environments.

Why it matters: For IAM and PAM teams, this matters because OT access control has to work across fragile legacy systems, remote operations, and operational continuity requirements without assuming a standard enterprise access model.


Context

Operational technology access is not governed like office IT access. OT environments often span legacy protocols, distributed sites, and systems that cannot tolerate the same change cadence as typical enterprise infrastructure, which makes privileged access control harder to enforce consistently.

The article uses analyst recognition to frame a practical governance question: whether PAM controls can support browser-based access, scalability, and compatibility across legacy OT systems without weakening operational continuity. That is the real issue for critical infrastructure, manufacturing, energy, and defence teams.

For identity programmes, the topic sits at the intersection of PAM, remote access governance, and industrial system constraints. The question is not whether access should be controlled, but whether the control model still works when the environment itself is geographically distributed and operationally sensitive.


Key questions

Q: How should security teams govern remote privileged access in OT environments?

A: They should treat OT remote access as privileged access governance, not simple connectivity. Access should be task-scoped, approved, recorded, and revoked automatically when the operational job ends. The strongest pattern is to tie every session to a change or maintenance record so accountability and containment are built into the workflow, not added after the fact.

Q: Why do legacy OT systems make PAM harder to govern?

A: Legacy OT systems often limit how much the control plane can be changed, so organisations rely on compensating access controls instead of refactoring the asset itself. That makes it easier for broad privileges and weak session boundaries to persist unless PAM enforcement is tested against real industrial workflows.

Q: What breaks when just-in-time access is not aligned to maintenance workflows?

A: Teams start bypassing the control to keep the plant running, which usually recreates standing privilege through exceptions and manual approvals. JIT only works when it matches how maintenance, support, and emergency access actually happen in OT.

Q: Should organisations treat browser-based OT access as a security control?

A: No. Browser-based access is a delivery method, not a governance outcome. It can make access easier to deploy and manage, but the security value comes from the policy layer, including authorization, session oversight, and revocation when the task is complete.


Technical breakdown

Browser-based secure remote access in OT environments

Browser-based access changes the delivery layer for OT connectivity, but it does not remove the identity problem. In industrial environments, remote access still has to bind a session to a specific user, purpose, and target asset while preserving operational continuity. The main architectural benefit is reducing client complexity across dispersed sites, which can help standardise access entry points. The risk is assuming that a browser front end alone satisfies governance. If the underlying authorization, session control, and logging are weak, the access path is simpler but not safer.

Practical implication: Treat browser access as an interface choice, not a control outcome, and verify the PAM policy stack behind it.

Just-in-time connectivity for distributed OT access

Just-in-time connectivity is the access pattern that matters most in this article. JIT means access is provisioned only when needed and for a narrow purpose, rather than left standing for operational convenience. In OT, this is attractive because distributed environments often need vendor, operator, and maintainer access across multiple sites. The governance challenge is that JIT must still align with maintenance windows, break-glass procedures, and asset criticality. If the approval model is too rigid, operations bypass it; if it is too loose, the standing privilege problem remains.

Practical implication: Map JIT approvals to OT maintenance and support workflows so temporary access remains auditable and operationally usable.

Legacy OT systems and protocol-agnostic access controls

Legacy OT systems are difficult because they often cannot be refactored quickly, but they still need modern access governance. Protocol-agnostic connectivity can reduce the need to modify the industrial stack, which is useful when downtime is expensive or unacceptable. The security issue is whether the access method preserves control granularity across heterogeneous protocols and inherited operational paths. Compatibility is not the same as governance. A control that works across old systems is only valuable if it still enforces identity, session boundaries, and least privilege at the point of use.

Practical implication: Test whether legacy compatibility preserves authorization boundaries rather than merely preserving connectivity.


NHI Mgmt Group analysis

OT access governance fails when organisations treat compatibility as the control objective. The article shows that browser access, scalability, and legacy support are being rewarded in the market, but those attributes do not by themselves govern identity risk. In OT, the control question is whether temporary access can be granted without expanding privilege across plants, vendors, and support paths. Practitioners should judge any PAM design by whether it constrains session scope at the moment of use.

Browser-based delivery does not solve the underlying privileged access model. A web front end can simplify deployment and user experience, yet OT governance still depends on whether the session is attributable, time-bound, and limited to the intended asset. That means the decisive issue is not the access channel, but the policy enforcement behind it. Teams should separate interface modernisation from actual privilege reduction.

Distributed OT access creates a governance gap between operational reality and entitlement design. Geographic spread, legacy constraints, and maintenance urgency push organisations toward broad exceptions if the programme is designed around enterprise IT assumptions. The market signal is that critical infrastructure teams need PAM models built for operational continuity, not just security ideals. Practitioners should expect their access design to survive maintenance pressure, not merely audit review.

Just-in-time access is becoming the practical test of OT privilege control. The article’s emphasis on advanced security controls compatibility across complex legacy systems points to a simple reality: standing access in industrial environments is increasingly hard to defend. JIT access is only credible when it fits the real work pattern of OT teams, including emergency support and vendor intervention. Practitioners should treat JIT fit as the measurement of programme maturity, not a feature checkbox.

What this signals

Compatibility is not governance: OT access modernisation often succeeds at reducing deployment friction while leaving privilege design untouched. Teams should test whether a new access path actually changes who can do what, for how long, and on which assets, or whether it simply repackages the old entitlement model in a browser.

Distributed industrial environments force PAM teams to think in sessions, not just accounts. When access must work across plants, vendors, and maintenance windows, the real measure is whether the control can limit authority at the point of use without creating standing exceptions.

The market signal here is that OT security buyers are increasingly evaluating access controls through operational continuity as much as through identity policy. That means identity teams need evidence that controls survive legacy constraints instead of assuming that enterprise IAM patterns will translate cleanly into industrial settings.


For practitioners

  • Map OT remote access by operational scenario Separate routine operator access, vendor support, and emergency break-glass use so each path has its own approval, session control, and audit trail. The goal is to prevent a single broad access pattern from covering all industrial access needs.
  • Enforce just-in-time access for maintenance work Grant privileged OT access only for a defined task and target scope, then revoke it automatically when the session ends or the maintenance window closes. This keeps temporary access from turning into standing privilege.
  • Test legacy-system compatibility against authorization boundaries Validate that browser-based or protocol-agnostic access still preserves least privilege, session isolation, and command-level control on older OT assets. Compatibility is insufficient if it weakens governance at the point of use.
  • Review vendor and third-party OT access governance Check whether outside maintainers have tightly scoped, time-limited access, clear sponsor ownership, and offboarding when the support relationship changes. OT programmes often fail when third-party access outlives the reason it was granted.

Key takeaways

  • OT access governance breaks down when teams optimise for compatibility but fail to constrain privilege at the session level.
  • The article frames browser-based access, scalability, and legacy compatibility as decision criteria for critical infrastructure teams, not just product features.
  • Practitioners should test whether PAM for OT actually delivers JIT control, session isolation, and revocation across distributed industrial environments.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIOT access controls in the article revolve around limiting privileged access in distributed environments.
Recommendation — Apply NHI-05 to constrain OT credentials to the minimum access needed for each session.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeThe article's PAM focus is fundamentally about preventing unnecessary privilege in industrial access paths.
Recommendation — Enforce AC-6 so OT sessions receive only the access required for the specific task.
CIS Controls v8CIS-5 — Account ManagementOT access governance depends on tightly controlled account creation, use, and revocation.
Recommendation — Use CIS-5 to inventory OT accounts and remove unused or excessive access.
NIST Zero Trust (SP 800-207)Least Privilege Access — Least Privilege AccessThe article repeatedly frames OT access through zero trust style, session-bound authorization.
Recommendation — Apply least-privilege access so OT connectivity is granted only for the specific need.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementOT privileged access abuse can enable credential use and movement across distributed environments.
Recommendation — Map OT access abuse to TA0006 and TA0008 to focus detection on credential misuse and spread.

Key terms

  • Operational Technology: Operational Technology is the hardware and software that monitors or controls physical processes such as manufacturing lines, utilities, and transportation systems. Unlike standard IT, OT prioritises uptime and safety, so identity controls must be precise enough to reduce risk without interrupting essential operations.
  • Just-in-Time Access Request: Just-in-Time Access Request is a pattern that grants access only when it is needed and only for the duration required. It reduces standing privilege by making access temporary, policy driven, and task scoped. This approach is especially useful for contractors, sensitive systems, and short-lived operational work.
  • PAM — Privileged Access Management: Solutions that control, monitor, and audit privileged access for both human and non-human identities. Traditional PAM tools are being extended to cover machine identities, service accounts, and agentic AI workloads.
  • Browser-mediated access: Browser-mediated access is access that is exercised through the browser rather than through a tightly controlled native client or backend workflow. It matters because many modern identity and data control failures occur after sign-in, during the live session where users interact with SaaS and AI tools.

Deepen your knowledge

NHI governance, identity lifecycle management, and workload identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org